← WordPress Vulnerabilities
WordPress security by component

wpstorecart

wpstorecart (wpstorecart) is a WordPress plugin with 2 published CVE records in this archive. The latest tracked vulnerability was published Sep 12, 2026; the highest published CVSS base score is 10.

Plugin slug: wpstorecart

CVE-2026-84099: wpstorecart exposes unauthenticated PHP object injection

wpstorecart through 5.0.7 allows direct unauthenticated access to a bundled add-on that deserializes caller-controlled input without restricting permitted classes. An attacker can inject arbitrary PHP objects and may escalate the primitive when a suitable gadget chain exists on the site. The authoritative export does not identify the add-on path, parameter, deserialization function, or a confirmed gadget chain.

PublishedSep 12, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for wpstorecart
Safe version
Sep 12, 2026 CVE-2026-84099
wpstorecart exposes unauthenticated PHP object injection
wpstorecart through 5.0.7 allows direct unauthenticated access to a bundled add-on that deserializes caller-controlled input without restricting permitted classes. An attacker can inject arbitrary PHP objects and may escalate the primitive when a suitable gadget chain exists on the site. The authoritative export does not identify the add-on path, parameter, deserialization function, or a confirmed gadget chain.
See mitigation notes
CVE8.1
NVDPending
Jun 16, 2012 CVE-2012-3576
Wpstorecart: A security weakness
Wpstorecart is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD10.0